
nono
safe execution paths for agents - zero trust, zero setup, zero latency.

safe execution paths for agents - zero trust, zero setup, zero latency.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…


Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

DejaVU - Open Source Deception Framework

IPSpinner works as a local proxy that redirects requests through external services.

A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.

Security event correlation engine for ELK stack

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…

MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)

AES-256 file and directory encryption tool with automatic upload to Anonfiles cloud storage, requiring a download ID for decryption and retrieval.

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

A POC on how to exploit CVE-2022-27518